CVE-2025-15538: Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15538?
CVE-2025-15538 is considered a high-severity vulnerability due to the potential for use after free exploitation.
Which versions of Assimp are affected by CVE-2025-15538?
CVE-2025-15538 affects Open Asset Import Library Assimp versions up to and including 6.0.2.
How do I fix CVE-2025-15538?
To fix CVE-2025-15538, upgrade your Assimp library to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-15538?
CVE-2025-15538 is a use after free vulnerability found in the Assimp library.
What impact does CVE-2025-15538 have on applications using Assimp?
The vulnerability can potentially lead to application crashes or execution of arbitrary code if exploited.